According to information released by Blockaid, their system has detected a malicious transaction event in real time, involving the theft of funds from VenusProtocol and other tokens, totaling $2 million. The attack method was a vulnerability in the 'arbitrary function call process' in the smart contract (address 0xb5cb...a87), which allowed the attacker to execute unauthorized code.
Blockaid utilizes a detection system that combines AI with blockchain data analysis, and it has now been integrated by several mainstream wallets and dApps. VenusProtocol officially clarified that the platform was not directly attacked, and the abnormal transfers were limited to external wallet accounts. This phenomenon is consistent with the warning issued by the FTC regarding blockchain scams in February 2025.
Source: https://x.com/blockaid_/status/1937727496268710019